LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-14-2003, 07:07 AM   #1
MJatIFAD
LQ Newbie
 
Registered: Aug 2003
Posts: 28

Rep: Reputation: 15
rwhod error messages


My syslog gets a lot of these messages:

rwhod[13350]: sendto(192.168.1.255): Operation not permitted

I found little usefull info about rwhod, but it seems to be sending UDP broadcasting packets. My system seems otherwise to work fine, network is running smoothly both with firewall and Samba.

I wonder whether I need to enable some permissions to get rid of these messages or maybe is worse than I think.

Is there someone that could enlighten me about this?

Cheers.
 
Old 09-14-2003, 05:07 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Maybe not polite to counter it with a question, but can you first check and make sure you *need* running/providing these services?
 
Old 09-15-2003, 11:27 AM   #3
MJatIFAD
LQ Newbie
 
Registered: Aug 2003
Posts: 28

Original Poster
Rep: Reputation: 15
What services are you referring to? I do not even know what services are using rwhod and what they are using it for. If I knew this I might be able to answer your question. I have tried to gather information about it but failed to find anything usefull.
 
Old 09-15-2003, 01:25 PM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
I do not even know what services are using rwhod and what they are using it for.
You could use your local manpages, man (1) rwho at LQ or query, say FOLDOC for it...

Firewall and Samba don't rely on the client rwho or the network daemon rwhod, so I'd say stop the service. Next run "netstat -an" and check any app which says "LISTEN" and think about if you need to run that app for yourself or anybody else. If unsure, stop and see if something breaks, then uninstall (can always reinstall later).
Lo and behold, you've taken your first steps towards hardening your box... Read on in the first sticky thread of this forum, post #1, under "checklists" and commence with a few securing/hardening docs, and run for instance Bastille, Tiger and Chkrootkit.

The "ops not permitted" is clearly an interface restriction thingie (192.168.1.255 being your subnet broadcast address), but what causes it? Causes can range from Netfilter to kernel patches.
If you really really need to know you could run rwhod under "strace".
 
Old 09-18-2003, 01:31 PM   #5
MJatIFAD
LQ Newbie
 
Registered: Aug 2003
Posts: 28

Original Poster
Rep: Reputation: 15
I turned off rwhod, which has removed the error messages. None of the services I was running seem to bother, so I guess this issue has been resolved for now. However, I never figured out what caused it, but this will have to be postponed for now. I have lots of real work to be finished...

Thank you for the tips and links. I appreciate it.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
rwhod listens but won't talk tifkat Slackware 6 03-07-2007 08:22 AM
Error messages ust Linux - Software 5 07-18-2005 10:31 AM
From where am i getting error messages to /var/log/messages? prabhuacsp Programming 3 02-16-2005 08:59 AM
From where am i getting error messages to /var/log/messages? prabhuacsp Linux - Networking 1 02-16-2005 12:34 AM
Rwhod???? l0f33t Linux - Security 2 08-11-2003 02:17 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:31 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration